MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
Incorrect escaping of a saved filter's owner allows an attacker to inject arbitrary HTML on systems where $g_show_user_realname = ON.
Cross-site scripting (XSS).
Note that By default, only users with Manager access level or above can save their filters publicly
$g_ show_user_realname = OFF; in configuration)g_stored_query_create_threshold / $g_stored_query_create_shared_threshold to NOBODYThanks to siunam (Tang Cheuk Hei) for discovering and responsibly reporting the issue.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(심각도 등급 추정치) | 80.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 80.00 |
VPI 공식 vpi-v1 기준